Skip to content

Latest commit

 

History

History
49 lines (39 loc) · 2.25 KB

File metadata and controls

49 lines (39 loc) · 2.25 KB

JML Standard Operating Procedure — Checklist

Organization: Meridian Trust Financial (illustrative) Owner: IAM / Identity Security Team Review cycle: Annually, or upon material process change


Joiner Checklist

  • HR record created in HRIS with role, department, manager, start date
  • Identity provisioned in Identity Provider (automated via SCIM or manual fallback)
  • Baseline access applied per role template
  • Non-standard access requests submitted, justified, and approved (manager + system owner)
  • SoD conflict check run against requested access
  • Access confirmed active before or on start date
  • Security awareness training assigned
  • Provisioning actions logged with timestamp and approver

Mover Checklist

  • Role change recorded in HRIS (new title, department, manager)
  • Access recertification triggered automatically
  • New-role baseline access provisioned
  • Old-role access explicitly reviewed for removal (not just left in place)
  • Old manager/system owner confirms removal or documents exception
  • SoD conflict check run against combined old + new access
  • Access delta (added/removed) logged with approver identity and timestamp

Leaver Checklist

  • Termination recorded in HRIS with effective date/time
  • Termination type classified (standard vs. high-risk)
  • Access disabled per SLA (same-day standard; before/at notification for high-risk)
  • VPN, remote sessions, and badge/physical access revoked
  • Manager confirms handover of shared mailboxes, files, and open tickets
  • Contractor/vendor-specific access confirmed included (not HRIS-only scope)
  • Access deleted/archived per data retention policy after retention window
  • Full timeline logged: termination time, disablement time, gap measured against SLA

Periodic Access Review Checklist

  • Review campaign generated for the scheduled system(s)
  • Entitlements presented with plain-language descriptions (not raw system codes)
  • Manager attestation completed
  • Independent system-owner review completed
  • Unattested/flagged access removed
  • Overdue reviews escalated per policy (e.g., 30-day escalation, 60-day auto-suspend)
  • Completion rate and evidence retained for audit